VYPR

Server

by Devolutions

CVEs (114)

  • CVE-2026-10787MedJun 8, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server…

  • CVE-2026-9246MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions…

  • CVE-2026-9224MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * …

  • CVE-2026-9223MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

  • CVE-2026-5171MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions…

  • CVE-2026-5146MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions…

  • CVE-2026-8407MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : *…

  • CVE-2026-4989MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from…

  • CVE-2026-1768MedFeb 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.

  • CVE-2025-13765MedNov 27, 2025
    risk 0.28cvss 4.3epss 0.00

    Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

  • CVE-2025-4316MedMay 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 2025.1.3.0 through…

  • CVE-2024-12148MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

  • CVE-2024-10971MedNov 12, 2024
    risk 0.28cvss 4.3epss 0.01

    Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.

  • CVE-2024-3545MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining…

  • CVE-2024-1901MedMar 5, 2024
    risk 0.28cvss 4.3epss 0.00

    Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable.

  • CVE-2024-1898MedMar 5, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator.

  • CVE-2025-11958MedOct 22, 2025
    risk 0.27cvss 4.1epss 0.00

    An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a crafted request.

  • CVE-2025-13758LowNov 27, 2025
    risk 0.23cvss 3.5epss 0.00

    Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

  • CVE-2024-2918LowApr 9, 2024
    risk 0.23cvss 3.6epss 0.00

    Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.

  • CVE-2026-9249LowMay 22, 2026
    risk 0.20cvss 3.1epss 0.00

    Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server…

Page 5 of 6